Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Certified Solution Specialist FCSS_SDW_AR-7.4 Questions and answers with ValidTests

Exam FCSS_SDW_AR-7.4 All Questions
Exam FCSS_SDW_AR-7.4 Premium Access

View all detail and faqs for the FCSS_SDW_AR-7.4 exam

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

Options:

A.

SD-WAN service rule 3 and interface HUB1-VPN2.

B.

SD-WAN service rule 3 and interface HUB1-VPN3.

C.

SD-WAN service rule 4 and port1or port2.

D.

SD-WAN service rule 4 and interface port2.

Expert Solution
Questions # 2:

Exhibit.

Question # 2

Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub 2

Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcutwith the spoke B2? (Choose two.)

Options:

A.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.

B.

On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.

C.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.

D.

On hubs, auto-diacovery-sender must be enabled on the IPsec VPNs to spokes

Expert Solution
Questions # 3:

When you use the command diagnose sys session list, how do you identify the sessions that correspond to traffic steered according to SD-WAN rules?

Options:

A.

You identify sessions steered according to SD-WAN rules with the flag vwl.

B.

You cannot identify SD-WAN sessions. You must use the sdwar. session filter.

C.

You identify sessions steered according to SD-WAN rules with the data vwl_mbr_seq.

D.

You identify sessions steered according to SD-WAN rules with the data 3dwan_service_id.

Expert Solution
Questions # 4:

Within the context of SD-WAN, what does SIA correspond to?

Options:

A.

Remote Breakout

B.

Local Breakout

C.

Software Internet Access

D.

Secure Internet Authorization

Expert Solution
Questions # 5:

You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD-WAN hub. Which overlay routing configuration should you use?

Options:

A.

BGP on loopback with dynamic BGP for ADVPN shortcut routing.

B.

BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.

C.

BGP per overlay with dynamic BGP for ADVPN shortcut routing.

D.

BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.

Expert Solution
Questions # 6:

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Interfaces

C.

Security profiles

D.

Traffic shaping

E.

Routing

Expert Solution
Questions # 7:

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

Options:

A.

Update the IPsec tunnel configurations on the hub.

B.

Update the SD-WAN configuration on the branches.

C.

Update the IPsec tunnel configuration on the branches.

D.

Delete the existing ADVPN configuration and configure ADVPN 2.0.

Expert Solution
Questions # 8:

Refer to the exhibits.

Question # 8

The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status.

Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

Options:

A.

Only related TCP traffic is used for performance measurement.

B.

The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.

C.

Encrypted traffic is not used for the performance measurement.

D.

FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.

Expert Solution
Questions # 9:

You are planning a new SD-WAN deployment with the following criteria:

- Two regions

- Most of the traffic is expected to remain within its region

- No requirement for inter-region ADVPN

To remain within the recommended best practices, which routing protocol should you select for the overlays?

Options:

A.

OSPF for the routing within each region and EBGP between the regions.

B.

IBGP with BGP on loopback within each region and EBGP between the regions.

C.

IBGP with BGP per overlays within each region and IBGP with BGP on loopback between the regions.

D.

IBGP within each region and between the regions.

Expert Solution
Questions # 10:

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FodiGate accepts the deletion and removes routes as required.

B.

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.

C.

FortiGate displays an error message. SD-WAN zones must contain at least two members

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions